Banking governance, prudential risk and compliance · 2026 series
Geopolitical Risk Appetite for Banks in 2026
How boards can translate geopolitical uncertainty into measurable appetite, limits, indicators and escalation.
The current challenge
Geopolitical risk cuts across credit, market, liquidity, operational, legal and conduct risk, yet ownership is often fragmented. The practical difficulty is that geopolitical events rarely remain within a single risk category. They transmit through customers, suppliers, markets, payment channels, technology, law, reputation and confidence. A control framework that reviews each dimension separately may therefore miss the combined exposure.
Decision-makers should distinguish verified events from assessment, and assessment from scenario. The aim is not to claim certainty about politics. It is to identify how a plausible event could affect the organisation, what evidence would change the view and which actions remain lawful and operationally achievable.
A risk-based compliance response
Create a common taxonomy, map transmission channels, link indicators to limits and assign escalation authority before a crisis. This response should be proportionate to exposure and grounded in current legal requirements. Jurisdiction, customer, product, transaction, distribution channel and technology all matter. Geography alone is neither a sufficient control nor evidence of misconduct.
- Define scope and ownership. Record which entities, products and decisions are covered and who may approve, stop or escalate activity.
- Map exposure and transmission. Connect direct counterparties with beneficial owners, intermediaries, suppliers, routes, currencies and critical technology.
- Use current authoritative data. Time-stamp sanctions lists, regulatory guidance and intelligence; preserve source lineage and confidence.
- Apply controls at decision points. Screen and investigate before onboarding, contracting, shipment, payment and material amendments—not only at account opening.
- Test effectiveness. Measure missed risk, false alerts, investigation quality, response time, overrides and repeat findings.
Scenario analysis
The scenario should be translated into observable drivers and tested across more than one severity. Teams should consider second-order effects, including customer behaviour, legal uncertainty, funding needs, market liquidity, operational capacity and the availability of insurance or alternative suppliers. Assumptions should be internally consistent and reviewed by both subject-matter and risk specialists.
Controls and evidence that withstand challenge
A defensible decision file explains what was known, when it was known, which rule or policy applied, how uncertainty was treated and why the action was proportionate. Useful evidence includes ownership records, source documents, screening results, investigator notes, model versions, approvals, exceptions and follow-up dates.
- Maintain a single inventory of legal obligations and internal controls.
- Re-screen material changes in parties, ownership, goods, route, vessel or payment structure.
- Separate automated alert generation from accountable decision-making.
- Set expiry dates for temporary overrides and enhanced-monitoring decisions.
- Report exposure, control effectiveness and unresolved uncertainty to the appropriate governance body.
Proportionality, legal interpretation and customer impact
Risk-based compliance is not the same as automatic de-risking. A control should respond to the specific legal obligation and evidenced risk, not to nationality or geography alone. Where activity is restricted, teams should identify whether a prohibition, licence, exemption, reporting duty or enhanced-control requirement applies. Legal interpretation must be current, documented and linked to the actual transaction.
Institutions should also test unintended consequences. Excessive friction can obstruct lawful trade, financial inclusion or humanitarian activity, while weak controls can expose the firm and society to serious harm. Good governance makes that trade-off visible, involves the right specialists and provides a route to challenge or appeal where appropriate.
Data, technology and human accountability
Technology can connect large volumes of ownership, transaction, vessel, trade and event data, but it also inherits missing fields, inconsistent identifiers and historical bias. Data quality should be measured at the decision level: whether the information is complete, timely and reliable enough for the particular action. Model outputs should state uncertainty and the important drivers behind a recommendation.
Human review is meaningful only when reviewers have sufficient time, competence, evidence and authority to disagree. Escalation teams should understand both the regulation and the underlying business. Overrides must be visible, reasoned and monitored; repeated overrides often indicate a policy, data or model problem rather than exceptional cases.
Metrics for management and the board
Volume statistics alone can create false comfort. Reporting should include exposure by risk driver, alert ageing, decision turnaround, high-risk overrides, data-quality gaps, failed controls, scenario loss ranges and whether agreed actions reduce vulnerability. Trends should be explained, not merely displayed.
Questions the board should ask
- Which geopolitical developments could breach appetite through more than one risk channel?
- Where are decisions dependent on stale ownership, country, supplier or technology data?
- Can critical controls continue during a cyber or payment-system disruption?
- Which scenarios would make current mitigants ineffective or legally unavailable?
- Are management actions specific, funded, owned and executable within the stress horizon?
Common failure modes
Typical weaknesses include treating a screening match as the whole risk assessment, relying on stale ownership data, using country scores without exposure logic, duplicating shocks across models, confusing the absence of an alert with evidence of safety, and allowing commercial urgency to bypass escalation. Each failure is fundamentally a governance problem as much as a technology problem.
Implementation roadmap
- First 30 days: identify material exposures, obligations, accountable owners and urgent control gaps.
- Days 31–60: connect data, scenarios, decision rules and escalation thresholds; test high-risk cases.
- Days 61–90: validate effectiveness, remediate findings, train users and establish board reporting.
Conclusion
How boards can translate geopolitical uncertainty into measurable appetite, limits, indicators and escalation. The strongest framework combines current legal interpretation, transparent risk analysis, reliable evidence and timely human accountability. Complexity is justified only when it improves a real decision.
Primary sources and further reading
- European Banking Authority — geopolitical risk and European resilience
- European Banking Authority — Risk Assessment Report, December 2025
Related analysis
- Sanctions Governance Across the Three Lines of Defence
- Geopolitical Scenarios in ICAAP
- Proliferation-Financing Controls for Banks
About the author
Jonas Adam Mohamed Osman Abdelghafour, known as Yonas Osman, publishes independent analysis on geopolitical risk, financial compliance, banking, insurance and quantitative risk modelling.
This article is educational analysis, not legal advice. Organisations should obtain advice for their jurisdictions and facts.